carta is a document converter: it ingests arbitrary, potentially untrusted input and renders it to another format. Safe handling of malformed input is a core goal.
carta is in early development. Security fixes are applied to the latest release and the main branch only. There is no long-term-support or back-porting commitment yet.
Please do not open a public issue for security problems.
Report privately through either channel:
- GitHub private vulnerability reporting (preferred)
- Email via max@kuatsu.de (if you would like an encrypted channel, say so in a first message)
Please include enough detail to reproduce the problem, ideally a minimal reproducer.
We aim to acknowledge a report within a few days. Please give us a reasonable window to release a fix before any public disclosure.